Cyber Resilience

CVE-2026-42833

CriticalUpdated

Published: 12 May 2026

Published
12 May 2026
Modified
01 June 2026
KEV Added
Patch
CVSS Score v3.1 9.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0075 50.3th percentile
Risk Priority 70 floored blend · peak EPSS

Summary

CVE-2026-42833 is a critical-severity Execution with Unnecessary Privileges (CWE-250) vulnerability in Microsoft Dynamics 365. Its CVSS base score is 9.1 (Critical).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 49.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

CWE-250 in network-accessible Dynamics 365 directly enables remote code execution via unnecessary privileges (T1190) and privilege escalation (T1068).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2025-62211Same product: Microsoft Dynamics 365
CVE-2026-32210Same product: Microsoft Dynamics 365
CVE-2025-62210Same product: Microsoft Dynamics 365
CVE-2026-42898Same product: Microsoft Dynamics 365
CVE-2025-26683Same vendor: Microsoft
CVE-2025-21177Same vendor: Microsoft
CVE-2025-59245Same vendor: Microsoft
CVE-2026-26125Same vendor: Microsoft
CVE-2025-59503Same vendor: Microsoft
CVE-2025-59246Same vendor: Microsoft

Affected Assets

microsoft
dynamics 365
9.1 — 9.1.45.11

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-250

Policy promotes least privilege by defining necessary privileges and management commitment to them.

addresses: CWE-250

Supervision detects and allows removal of unnecessary privileges that enable execution with excess rights.

addresses: CWE-250

Reviewing accounts for compliance, disabling/removing unneeded accounts, and aligning with termination processes prevents execution with unnecessary privileges.

addresses: CWE-250

Separation of duties prevents any single user from holding all privileges needed to complete a critical task, directly reducing execution with unnecessary privileges.

addresses: CWE-250

Directly prevents execution with more privileges than needed for assigned tasks.

addresses: CWE-250

Role-based training on least privilege principles reduces the chance personnel assign or retain unnecessary privileges.

addresses: CWE-250

Analysis of audit records can identify execution with unnecessary privileges through unusual activity patterns.

addresses: CWE-250

Automatic termination after a defined period eliminates unnecessary privileges from persistent connections.

References